RajinKerja
Back

Privacy Policy

RajinKerja · Governed by the laws of Malaysia · PDPA 2010

1. Who we are

RajinKerja is a self-hosted staff attendance system operated at rajinkerja.com by the employing organisation ("the Operator"), which is the data user for the purposes of the Personal Data Protection Act 2010 ("PDPA").

2. What we collect

Account data (name, employee ID, email, phone, role); attendance data (clock-in/out selfies, encrypted facial templates, GPS coordinates and accuracy, timestamps, optional work summaries); PDPA acceptance records including the acceptance selfie; and technical data (browser user-agent, IP address, audit log entries).

3. Why we collect it (purposes)

Verifying identity at clock-in/out; preventing attendance fraud; supervisor review of punches; producing attendance, working-hours and payroll-supporting reports; account security (login auditing, lockouts); and compliance with employment and statutory record-keeping obligations.

4. Sensitive personal data

Facial images and facial templates are sensitive personal data. They are processed only with your explicit consent, recorded in-app together with your acceptance selfie, per section 40 PDPA. You may withdraw consent through HR at any time; alternative attendance arrangements will then apply.

5. Storage, security and retention

All data is stored on the Operator's own self-hosted infrastructure — the Service makes no outbound calls to third-party services at runtime. Facial templates are encrypted (AES-256-GCM). Passwords are hashed with Argon2id. Punch selfies are automatically deleted after the configured retention period (default 180 days); attendance records themselves are retained per employment record-keeping requirements. Facial templates and reference photos are destroyed when an account is deleted.

6. Disclosure

Personal data is not sold. Biometric data is not disclosed to any third party. Attendance records may be disclosed to persons authorised by the Operator (HR, payroll, auditors) and where required by Malaysian law or a competent authority.

7. Your rights

Under the PDPA you have the right to access and correct your personal data, to withdraw consent, and to limit processing. Requests should be made to your employer's HR department, which will respond within the periods prescribed by the PDPA.

8. Notis Ringkas (Bahasa Malaysia)

RajinKerja memproses data peribadi anda — termasuk data biometrik sensitif (imej dan templat wajah), lokasi GPS dan rekod kehadiran — untuk tujuan pengesahan kehadiran, pencegahan penipuan, semakan penyelia dan laporan berkaitan gaji, menurut Akta Perlindungan Data Peribadi 2010. Data disimpan pada sistem layan-diri Pengendali, disulitkan, dan tidak didedahkan kepada pihak ketiga. Anda berhak mengakses dan membetulkan data anda serta menarik balik persetujuan melalui jabatan HR majikan anda.

9. Changes and contact

The Operator may update this policy; material changes will be notified in-app. Questions and PDPA requests: your employer's HR department or system administrator.